PLAY PODCASTS
Ezuri: Regenerating a different kind of target.
Season 3 · Episode 177

Ezuri: Regenerating a different kind of target.

Research Saturday · N2K Networks

April 3, 202119m 16s

Audio is streamed directly from the publisher (pdst.fm) as published in their RSS feed. Play Podcasts does not host this file. Rights-holders can request removal through the copyright & takedown page.

Show Notes

Guests Fernando Martinez and Tom Hegel from AT&T Alien Labs join Dave to discuss their team's research "Malware using new Ezuri memory loader." Multiple threat actors have recently started using a Go language (Golang) tool to act as a packer and avoid Antivirus detection. Additionally, the Ezuri memory loader tool acts as a malware loader and executes its payload in memory, without writing the file to disk. While this technique is known and commonly used by Windows malware, it is less popular in Linux environments.

The research can be found here:

Learn more about your ad choices. Visit megaphone.fm/adchoices